[WID-SEC-2024-0679] Apache Commons: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.6 (mittel) Remoteangriff ja Datum 20.03.2024 Stand UPDATE 09.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Produktbeschreibung Apache Commons ist ein Apache-Projekt, das alle Aspekte der wiederverwendbaren Java-Komponenten behandelt. Produkte UPDATE 08.06.2026 SolarWinds Platform <2026.2 UPDATE 16.10.2025 IBM QRadar SIEM UPDATE 14.05.2025 IBM QRadar SIEM <7.5.0 UP12 UPDATE 15.10.2024 Atlassian Confluence <8.9.3-8.9.7 > Atlassian Confluence <8.5.11-8.5.16 (LTS) > Atlassian Confluence <7.19.26-7.19.28 (LTS)) > UPDATE 19.06.2024 Red Hat Enterprise Linux UPDATE 18.06.2024 Atlassian Confluence Data Center <8.9.3 Atlassian Confluence <8.5.11 LTS Atlassian Confluence <7.19.24 LTS UPDATE 21.05.2024 Red Hat JBoss A-MQ Broker <7.12.0 UPDATE 22.04.2024 SUSE Linux UPDATE 21.03.2024 Fedora Linux 20.03.2024 Apache Commons Configuration <2.10.1 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Apache Commons ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple unspecified vulnerabilities in Apache Commons Configuration (CVSS 7.3) allow for a remote attack vector, though the article does not detail the specific attack method. The primary affected version is Apache Commons Configuration prior to 2.10.1. The advisory specifies upgrading to version 2.10.1 as the mitigation.